PT-2025-41504 · WordPress · Booking Manager

·

CVE-2025-10124

·

Published

2025-10-10

·

Updated

2025-10-10

CVSS v3.1

4.5

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Booking Manager WordPress plugin versions prior to 2.1.15
Description The Booking Manager WordPress plugin has an issue where a shortcode capable of deleting bookings is registered and accessible to users with contributor privileges or higher. Visiting a page containing this shortcode results in the deletion of bookings.
Recommendations Update The Booking Manager WordPress plugin to version 2.1.15 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-10124

Affected Products

Booking Manager